Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

A company runs a three-tier web application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier on TCP port 8080. The company wants to enforce these requirements at the network level with minimal administrative overhead and without relying on instance-level firewall software. What should they do?

⚠ Common exam trap

The trap here is assuming that creating separate VPCs or subnets automatically restricts traffic between tiers, when in fact firewall rules must explicitly allow the required flows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a VPC firewall rule that allows TCP port 8080 from the web tier's network tag to the application tier's network tag, and another rule that allows the database port from the application tier's network tag to the database tier's network tag.

Tag-based VPC firewall rules are the standard way to enforce tier-to-tier access on Compute Engine. By allowing only TCP 8080 from the web tier tag to the application tier tag, and only the database port from the application tier tag to the database tier tag, the company implements least-privilege network segmentation centrally. This avoids instance-level firewall software and keeps administration simple.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a VPC firewall rule that allows TCP port 8080 from the web tier's network tag to the application tier's network tag, and another rule that allows the database port from the application tier's network tag to the database tier's network tag.

    Why this is correct

    VPC firewall rules use source and target tags to scope traffic to specific instances. Allowing TCP 8080 from the web tier tag to the application tier tag enforces the web-to-app path, and allowing the database port from the app tier tag to the database tier tag enforces the app-to-database path. This meets the requirement at the network level without instance-level software.

  • ✗

    Place the database tier in a separate VPC and use VPC Network Peering to connect it to the application tier's VPC, then allow all traffic between the peered networks.

    Why it's wrong here

    VPC Network Peering connects networks but does not by itself restrict traffic to specific tiers or ports. Allowing all traffic between peered networks would permit the web tier to reach the database tier, violating the requirement. Peering also adds complexity without providing the granular, tag-based enforcement needed here.

  • ✗

    Configure each instance with iptables rules that permit only the required traffic, and disable VPC firewall rules for the project.

    Why it's wrong here

    Using iptables on each instance introduces instance-level firewall software, which the company explicitly wants to avoid. Disabling VPC firewall rules also removes the centralized network-level control and can expose instances. This approach increases administrative overhead and does not meet the requirement for minimal overhead and network-level enforcement.

  • ✗

    Create a single VPC firewall rule that allows all TCP traffic between all instances in the VPC, and rely on the application code to restrict access.

    Why it's wrong here

    A single rule allowing all TCP traffic between all instances removes network-level segmentation. The database tier would be reachable from the web tier and any other instance, violating the requirement that the database be reachable only from the application tier. Relying on application code also contradicts the requirement to avoid instance-level controls and increases risk.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.